CVE-2017-7525 PUBLISHED

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

EPSS 79.55% · 99.1th percentile

Risk Scores

EPSS Score
79.55%
99.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibjackson-json-java1.9.13-1, 0
Ubuntu:Pro:16.04:LTSjackson-databind2.4.2-2, 0, 2.4.2-3
Ubuntu:18.04:LTSlibjackson-json-java1.9.2-9, 1.9.2-8, 0
Ubuntu:Pro:14.04:LTSjackson-databind0, 2.2.2-1
Ubuntu:Pro:14.04:LTSlibjackson-json-java1.9.2-3, 1.9.2-2, 1.9.2-1
Ubuntu:16.04:LTSlibjackson-json-java1.9.2-3, 1.9.2-7, 0

Timeline

References

Open in Interactive Console →